VYPR
High severity7.8CISA KEVNVD Advisory· Published Aug 24, 2021· Updated Jun 17, 2026

CVE-2021-30860

CVE-2021-30860

Description

An integer overflow was addressed with improved input validation. This issue is fixed in Security Update 2021-005 Catalina, iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6, watchOS 7.6.2. Processing a maliciously crafted PDF may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

20
  • cpe:2.3:a:freedesktop:poppler:*:*:*:*:*:*:*:*
    Range: <22.09.0
  • cpe:2.3:a:xpdfreader:xpdf:*:*:*:*:*:*:*:*
    Range: <4.04
  • cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
    Range: <14.8
  • cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
    Range: <12.5.5
  • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*range: >=10.15,<10.15.7
    • cpe:2.3:o:apple:mac_os_x:10.15.7:-:*:*:*:*:*:*
    • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*
    • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020:*:*:*:*:*:*
    • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*
    • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:*
    • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:*
    • cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-004:*:*:*:*:*:*
  • Apple Inc./macOS2 versions
    cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*range: <11.6
    • (no CPE)range: unspecified
  • cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:apple:watchos:*:*:*:*:*:*:*:*range: <7.6.2
    • (no CPE)range: unspecified
  • Range: before Security Update 2021-005
  • Range: <11.6
  • Apple Inc./iOSllm-fuzzy2 versions
    <14.8+ 1 more
    • (no CPE)range: <14.8
    • (no CPE)range: unspecified

Patches

Vulnerability mechanics

References

16

News mentions

0

No linked articles in our index yet.